Encrypt Data with the Deterministic Encryption Scheme
- From Setup, in the Quick Find box, enter Platform Encryption, and then select Key Management.
- From the Choose Tenant Secret Type menu, select Data inSalesforce.
- Generate or upload a tenant secret.
- From Setup, in the Quick Find box, enter Platform Encryption, and then select Advanced Settings.
- Enable Deterministic Encryption.
- From Setup, select Key Management.
- Select the Data in Salesforce (Deterministic) secret type.
- Generate a tenant secret.You can mix and match probabilistic and deterministic encryption, encrypting some fields one way and some fields the other.
- Enable encryption for each field, specifying the deterministic encryption scheme. How you do that depends on whether it’s a standard field or a custom field.For standard fields, from Setup, select Encryption Policy,and then select Encrypt Fields. For each field you want toencrypt, select the field name, and then choose Deterministicfrom the Encryption Scheme list. For custom fields, open the Object Manager and edit the field you want to encrypt.Select Encrypt the contents of this field, and select Use case sensitive deterministic encryption.
- For standard fields, from Setup, select Encryption Policy,and then select Encrypt Fields. For each field you want toencrypt, select the field name, and then choose Deterministicfrom the Encryption Scheme list.
- For custom fields, open the Object Manager and edit the field you want to encrypt.Select Encrypt the contents of this field, and select Use case sensitive deterministic encryption.
- To encrypt your existing data with the active Data in Salesforce (Deterministic) key material, contact Salesforce Support. If you change the encryption scheme for a field from Deterministic to Probabilistic, contact Salesforce to re-encrypt data in that field with your active Data in Salesforce key material.